- What is the NCSC-FI CNA?
- NCSC-FI is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 10 CVE records since 2024.
- How many CVEs has NCSC-FI published?
- NCSC-FI has published 10 CVE records, including 10 in the last two years.
- What is NCSC-FI's CVE data quality grade?
- RadicalNotion.AI grades NCSC-FI's CVE data quality as A, with an overall completeness score of 100%. This reflects how consistently its CVE records include vendor (100%), product (100%), CVSS (100%), and CWE (100%) information.
- What products does NCSC-FI publish CVEs for?
- NCSC-FI most frequently publishes CVEs for Pro Cloud Server, Valmet DNA, LAPSWebUI, Sparx Pro Cloud Server, Sparx Enterprise Architect.
- Which vendors does NCSC-FI cover?
- NCSC-FI publishes CVEs across 6 distinct vendors, most often Sparx Systems Pty Ltd., Valmet, Truesec, cerberusftp, danofficeit.
- Is NCSC-FI actively publishing CVEs?
- NCSC-FI is currently active, based on 10 CVEs in the last two years.
- What is the average severity of NCSC-FI's CVEs?
- The average CVSS base score across NCSC-FI's scored CVEs is 7.5.
- How many critical CVEs has NCSC-FI published?
- NCSC-FI has published 4 critical-severity CVEs and 9 high-severity CVEs.
- Are any of NCSC-FI's CVEs in CISA's Known Exploited Vulnerabilities catalog?
- No. None of NCSC-FI's CVEs are currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- What are the most common weakness types in NCSC-FI's CVEs?
- NCSC-FI's CVEs most often map to these CWE weakness types: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-250 (Execution with Unnecessary Privileges), CWE-522 (Insufficiently Protected Credentials), CWE-613 (Insufficient Session Expiration).
- How does NCSC-FI rank among CNAs?
- By total CVE volume, NCSC-FI ranks #305 of 370 CNAs, and it reports more complete CVE records than 60% of all CNAs.